Malware

Bulz.870204 removal guide

Malware Removal

The Bulz.870204 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.870204 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

How to determine Bulz.870204?


File Info:

name: 1B41901401549767FEBF.mlw
path: /opt/CAPEv2/storage/binaries/ffc87ba2fab0145fb690942229731855f09201fad53bd9f395cf50109f6394dd
crc32: C9185FC1
md5: 1b41901401549767febf40b59bf99ab3
sha1: f7e0349e2c6c678af63e40a4d724fccbda6d1c6c
sha256: ffc87ba2fab0145fb690942229731855f09201fad53bd9f395cf50109f6394dd
sha512: 450ccc7586a3521a5248af18dd03603fe8d613fb131dac47617840f07cfbae690b924f93f27cf99702aa805e8a62dd773defe362c5b5090513ea71439ee71f82
ssdeep: 49152:Nqe3f6+G/RusAcGbgg9EgisYuunxE+DidXvh6dS/04OOR5QvDX:cSi+GIhbR9EQYXnxE+DidXvh6d204OOY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14CD5F13FB268653ED4AA0B3245B39350987BBA61B81B8C1F47F0091DCF664711E3FA55
sha3_384: 3ab890fb14639156c21e810902c74d29451f9b84807aa270df5da268ba7f6dce6961a13649f227efaa4a69f4062df937
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-11-15 09:48:30

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Spider703 Inc.
FileDescription: AutoMiner Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: AutoMiner
ProductVersion: v3.0.3
Translation: 0x0000 0x04b0

Bulz.870204 also known as:

LionicTrojan.Win32.Convagent.4!c
MicroWorld-eScanGen:Variant.Bulz.870204
FireEyeGen:Variant.Bulz.870204
McAfeeArtemis!1B4190140154
SangforRiskware.Script.BitMiner.gen
AlibabaRiskWare:Script/BitMiner.fe688245
Cybereasonmalicious.401549
SymantecTrojan.Gen.MBT
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Bulz.870204
AvastWin32:Malware-gen
TencentScript.Risk.Bitminer.Dyqj
McAfee-GW-EditionBehavesLike.Win32.CSDImonetize.vc
EmsisoftGen:Variant.Bulz.870204 (B)
GDataGen:Variant.Bulz.870204
GridinsoftRansom.Win32.Gen.sa
ArcabitTrojan.Bulz.DD473C
MicrosoftProgram:Win32/Uwamson.A!ml
ALYacGen:Variant.Bulz.870204
MAXmalware (ai score=87)
VBA32Trojan.Convagent
TrendMicro-HouseCallTROJ_GEN.R002H07L621
FortinetRiskware/Miner
AVGWin32:Malware-gen

How to remove Bulz.870204?

Bulz.870204 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment